< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Proxmox VE vulnerability allows passwordless login

A critical security vulnerability has been identified in Proxmox VE, allowing attackers to bypass authentication and log into vulnerable systems without a valid password. The flaw, tracked as CVE-2023-54391, stems from an error in how two-factor authentication is handled via the API endpoint /api2/json/access/ticket. By manipulating the 'sfa-challenge' parameter, an attacker can skip a crucial authentication step.

The vulnerability affects Proxmox VE 7 (versions 7.0 through 7.4) and early installations of Proxmox VE 8 (up to version 8.0.4). Notably, the issue was inadvertently addressed in a 2023 code update, though its security implications were not recognized at the time. Administrators have already reported instances of compromised hosts and systems damaged by ransomware due to this flaw.

VulnCheck has assigned the vulnerability high severity scores, including a CVSS 3.1 rating of 9.8 out of 10. Currently supported versions of Proxmox VE are not affected. To mitigate risks, administrators are advised to secure management interfaces and verify the version of the 'libpve-access-control' package.

Entities

Proxmox